# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=166

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 167

---

## [Dashboard table: color boolean cell](https://discuss.elastic.co/t/dashboard-table-color-boolean-cell/320274)

<div class="topic-metadata">

**Author:** [@emmanuel\_t](https://discuss.elastic.co/u/emmanuel_t)\
**Replies:** 2\
**Last updated:** [December 2, 2022, 9:18am UTC](https://discuss.elastic.co/t/dashboard-table-color-boolean-cell/320274 "2022-12-02T09:18:12Z")

</div>

Hello, I have boolean data in my index, that I'm rendering in a dashboard table (currently lens, but I could change to another system, as long as the final rendering looks like a table). I would like to color the boolea…

---

## [Separate filtered queries for source and destination fields in vega sankey visualization](https://discuss.elastic.co/t/separate-filtered-queries-for-source-and-destination-fields-in-vega-sankey-visualization/320251)

<div class="topic-metadata">

**Author:** [@Senol\_Kurt](https://discuss.elastic.co/u/Senol_Kurt)\
**Replies:** 1\
**Last updated:** [December 2, 2022, 8:54am UTC](https://discuss.elastic.co/t/separate-filtered-queries-for-source-and-destination-fields-in-vega-sankey-visualization/320251 "2022-12-02T08:54:01Z")

</div>

I want to create a sankey chart using a single field. Both my source and destination data are stored in that field. Is it possible to use separate filters for source and destination data?

---

## [Multiple ingest pipeline in index template](https://discuss.elastic.co/t/multiple-ingest-pipeline-in-index-template/319793)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 2\
**Last updated:** [December 2, 2022, 7:28am UTC](https://discuss.elastic.co/t/multiple-ingest-pipeline-in-index-template/319793 "2022-12-02T07:28:14Z")

</div>

Hello! I have index template and need attach 2 ingest pipelines to him. How I can do it? My current config { "index": { "default\_pipeline": "netflow-pipeline" } }

---

## [【Kibana】The line graph problem](https://discuss.elastic.co/t/kibana-the-line-graph-problem/320245)

<div class="topic-metadata">

**Author:** [@ydbdyds](https://discuss.elastic.co/u/ydbdyds)\
**Replies:** 2\
**Last updated:** [December 2, 2022, 2:36am UTC](https://discuss.elastic.co/t/kibana-the-line-graph-problem/320245 "2022-12-02T02:36:11Z")

</div>

I had a problem drawing with Kibana ，Every day I generate a document that looks like the following data structure { "reports":\[ { "url":"test1", "method":"get", "val1":40…

---

## [App search Analytics in Kibana (logs-app\_search.analytics-default)](https://discuss.elastic.co/t/app-search-analytics-in-kibana-logs-app-search-analytics-default/317657)

<div class="topic-metadata">

**Author:** [@moassafiri](https://discuss.elastic.co/u/moassafiri)\
**Replies:** 1\
**Last updated:** [November 4, 2022, 3:17am UTC](https://discuss.elastic.co/t/app-search-analytics-in-kibana-logs-app-search-analytics-default/317657 "2022-11-04T03:17:14Z")

</div>

Is there a way to Filter based on the Engine name from the logs-app\_search.analytics-default Data stream? I can see labels.engine\_id; but this returns a UUID which is not user-friendly. Especially when doing Drill-downs …

---

## [Syntax for Pipeline Processor Condition in Kibana](https://discuss.elastic.co/t/syntax-for-pipeline-processor-condition-in-kibana/320303)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 1\
**Last updated:** [December 1, 2022, 10:50pm UTC](https://discuss.elastic.co/t/syntax-for-pipeline-processor-condition-in-kibana/320303 "2022-12-01T22:50:52Z")

</div>

I would like to write a pipeline that drops the field "A" from a document when its value is the string "None". I want to do this in the Kibana UI. I figure I need a Remove processor when runs on the condition that A == …

---

## [Re-configure kibana to new cluster](https://discuss.elastic.co/t/re-configure-kibana-to-new-cluster/318068)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 10:04pm UTC](https://discuss.elastic.co/t/re-configure-kibana-to-new-cluster/318068 "2022-11-03T22:04:35Z")

</div>

My kibana is already enrolled on a cluster, but the cluster failed to boot (the PC failed to boot and will be reinstalled). Can I reconfigure kibana to a new cluster? I don't care about losing existing data in kibana as …

---

## [Kibana stills warns about snapshots with the same Schedule](https://discuss.elastic.co/t/kibana-stills-warns-about-snapshots-with-the-same-schedule/320294)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 8:46pm UTC](https://discuss.elastic.co/t/kibana-stills-warns-about-snapshots-with-the-same-schedule/320294 "2022-12-01T20:46:26Z")

</div>

Hello, I'm on version 8.5.1 and just saw that Kibana still warns about two or more policies having the same Schedule. From elasticsearch documentation this is not an issue as multiple snapshots can be taken at the sa…

---

## [Difference of aggregated value that grouped by two fields across time](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906)

<div class="topic-metadata">

**Author:** [@amylyu](https://discuss.elastic.co/u/amylyu)\
**Replies:** 7\
**Last updated:** [November 3, 2022, 5:50pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906 "2022-11-03T17:50:25Z")

</div>

Hi, we are getting data into elastic through Kafka Prometheus endpoint and trying to create a visualization which would help us show latest ingestion rate in each kafka topics. In order to achieve this, we need to group …

---

## [Kiabana completing setup blocked](https://discuss.elastic.co/t/kiabana-completing-setup-blocked/319497)

<div class="topic-metadata">

**Author:** [@ardue](https://discuss.elastic.co/u/ardue)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 3:33pm UTC](https://discuss.elastic.co/t/kiabana-completing-setup-blocked/319497 "2022-12-01T15:33:44Z")

</div>

Hello, I have a problem with kibana, when connecting elasticsearch on kibana, it remains blocked on "completing setup" Here is the error in the log Action failed with '\[index\_not\_green\_timeout\] Timeout waiting for t…

---

## [/internal/bsearch returned 405 - not allowed in Kibana Discover screen](https://discuss.elastic.co/t/internal-bsearch-returned-405-not-allowed-in-kibana-discover-screen/319366)

<div class="topic-metadata">

**Author:** [@david-n](https://discuss.elastic.co/u/david-n)\
**Replies:** 3\
**Last updated:** [December 1, 2022, 3:09pm UTC](https://discuss.elastic.co/t/internal-bsearch-returned-405-not-allowed-in-kibana-discover-screen/319366 "2022-12-01T15:09:03Z")

</div>

Hello everyone, I'm working on an application to analyze my spending. The idea is to store all bank account transactions in Elasticsearch and analyze them using Kibana. For now I have a local development environment bas…

---

## [Kibana starting with fatal error no such file](https://discuss.elastic.co/t/kibana-starting-with-fatal-error-no-such-file/319983)

<div class="topic-metadata">

**Author:** [@steves](https://discuss.elastic.co/u/steves)\
**Replies:** 10\
**Last updated:** [December 1, 2022, 10:33am UTC](https://discuss.elastic.co/t/kibana-starting-with-fatal-error-no-such-file/319983 "2022-12-01T10:33:11Z")

</div>

I just installed Kibana after getting Elasticsearch running (secure), both installed with apt, on an Ubuntu 22.04 Server. I start Kibana with systemctl start kibana.service or for debugging ./bin/kibana which results …

---

## [Would like to arrange data histogram COUNT values in descending order,Vertical bar](https://discuss.elastic.co/t/would-like-to-arrange-data-histogram-count-values-in-descending-order-vertical-bar/318072)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 3, 2022, 12:06pm UTC](https://discuss.elastic.co/t/would-like-to-arrange-data-histogram-count-values-in-descending-order-vertical-bar/318072 "2022-11-03T12:06:15Z")

</div>

Hello All, Is it possible to arrange data histogram COUNT values in descending order(big to small). Simply need to display highestest count first for given product type on given date. I dont see any option available t…

---

## [Elasticsearch how to subtract field number value with specific number](https://discuss.elastic.co/t/elasticsearch-how-to-subtract-field-number-value-with-specific-number/318090)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 11:44am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-subtract-field-number-value-with-specific-number/318090 "2022-11-03T11:44:36Z")

</div>

Hello I am looking for solution to prepare dashboard in which i need to prepare a visualization with difference value e.g. site performance field mentioned as 500ms but as per threshold it should be 200ms Field name "…

---

## [Official icon name](https://discuss.elastic.co/t/official-icon-name/320181)

<div class="topic-metadata">

**Author:** [@seanee](https://discuss.elastic.co/u/seanee)\
**Replies:** 2\
**Last updated:** [November 30, 2022, 8:03pm UTC](https://discuss.elastic.co/t/official-icon-name/320181 "2022-11-30T20:03:03Z")

</div>

I'm creating user documentation and was wondering, is there an official name for the menu icon in the upper left of the Kibana GUI (the three lines) other than menu icon . I keep referring to it as a 'pancake icon' as it…

---

## [V 8.5.0 update - boolean field not working in donut lens anymore](https://discuss.elastic.co/t/v-8-5-0-update-boolean-field-not-working-in-donut-lens-anymore/318949)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 11\
**Last updated:** [November 30, 2022, 5:20pm UTC](https://discuss.elastic.co/t/v-8-5-0-update-boolean-field-not-working-in-donut-lens-anymore/318949 "2022-11-30T17:20:39Z")

</div>

Dear All, recently I updated to version 8.5.0 Since that time a donut lens isn't working. This mapping for this donat is defined with "bq\_DMZ": { "type": "boolean" }, With logstash I am importing the d…

---

## [Changing the timezone does not change how far the logs are from the current time](https://discuss.elastic.co/t/changing-the-timezone-does-not-change-how-far-the-logs-are-from-the-current-time/319753)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee\_Fox](https://discuss.elastic.co/u/Hemabh_Ravee_Fox)\
**Replies:** 6\
**Last updated:** [November 30, 2022, 3:41pm UTC](https://discuss.elastic.co/t/changing-the-timezone-does-not-change-how-far-the-logs-are-from-the-current-time/319753 "2022-11-30T15:41:55Z")

</div>

I am using a locally deployed elasticsearch and kibana. When I send data to an index with the current timestamp - in kibana it is displayed as being 5:30 hours ahead of the current time. I came to understand that this i…

---

## [Permanent filter on data view](https://discuss.elastic.co/t/permanent-filter-on-data-view/317993)

<div class="topic-metadata">

**Author:** [@Joseph\_Predignac](https://discuss.elastic.co/u/Joseph_Predignac)\
**Replies:** 2\
**Last updated:** [November 3, 2022, 9:24am UTC](https://discuss.elastic.co/t/permanent-filter-on-data-view/317993 "2022-11-03T09:24:15Z")

</div>

Hi everyone, I work with o365 logs, and I want to make exceptions on some users, some countries etc... For example, on a dashboard, I focus on login from countries except mine, to see suspicious logs. But, if I know a u…

---

## [Field conversion - Transforming Unix Time into Date](https://discuss.elastic.co/t/field-conversion-transforming-unix-time-into-date/320063)

<div class="topic-metadata">

**Author:** [@pedrodantas](https://discuss.elastic.co/u/pedrodantas)\
**Replies:** 4\
**Last updated:** [November 30, 2022, 3:20pm UTC](https://discuss.elastic.co/t/field-conversion-transforming-unix-time-into-date/320063 "2022-11-30T15:20:58Z")

</div>

Hello! I was wondering if there is a way to convert a field that is being received in Unix Time (long) into a fully readable Date in the Kibana environment. My application is sending JSON logs to Kibana. Two of the log…

---

## [Help on IF statement in Kibana painless script](https://discuss.elastic.co/t/help-on-if-statement-in-kibana-painless-script/320024)

<div class="topic-metadata">

**Author:** [@auato](https://discuss.elastic.co/u/auato)\
**Replies:** 6\
**Last updated:** [November 30, 2022, 2:07pm UTC](https://discuss.elastic.co/t/help-on-if-statement-in-kibana-painless-script/320024 "2022-11-30T14:07:51Z")

</div>

This script below works fine but I would like to insert an IF statement that executes these lines of code only in the case a third '\_' character is present in the field 'measurement', otherwise it does not execute anythi…

---

## [Timelion query to string containing slash "/" -- aka: howto use regexp in timelion](https://discuss.elastic.co/t/timelion-query-to-string-containing-slash-aka-howto-use-regexp-in-timelion/320158)

<div class="topic-metadata">

**Author:** [@DrG](https://discuss.elastic.co/u/DrG)\
**Replies:** 0\
**Last updated:** [November 30, 2022, 1:58pm UTC](https://discuss.elastic.co/t/timelion-query-to-string-containing-slash-aka-howto-use-regexp-in-timelion/320158 "2022-11-30T13:58:52Z")

</div>

Hello everybody, in the database, a set of strings (stringified ids) are there, stemming from a directory view. Now I like to filter out subfolders - aka filter out those elements containing slash(es). the database co…

---

## [Kibana (code=exited, status=78)](https://discuss.elastic.co/t/kibana-code-exited-status-78/319819)

<div class="topic-metadata">

**Author:** [@barnabe](https://discuss.elastic.co/u/barnabe)\
**Replies:** 6\
**Last updated:** [November 30, 2022, 1:17pm UTC](https://discuss.elastic.co/t/kibana-code-exited-status-78/319819 "2022-11-30T13:17:39Z")

</div>

Hello, I have a problem, Kibana is not starting for reasons that escape me I m not sure how to describe it best so here are the log and config files for Elasticsearch and Kibana as well as the error. the error kali ~ …

---

## [Visualization Color change from 6.0 to 7.0](https://discuss.elastic.co/t/visualization-color-change-from-6-0-to-7-0/319868)

<div class="topic-metadata">

**Author:** [@MorpheusPgh](https://discuss.elastic.co/u/MorpheusPgh)\
**Replies:** 2\
**Last updated:** [November 30, 2022, 11:20am UTC](https://discuss.elastic.co/t/visualization-color-change-from-6-0-to-7-0/319868 "2022-11-30T11:20:47Z")

</div>

I am importing my Visualizations from a Previous version of Kibana. Red was the Default first color, and in the latest release (7.17.4) the color schemes are completely different. How do I get a return to the colors I …

---

## [Unable to see Timeline Section](https://discuss.elastic.co/t/unable-to-see-timeline-section/320070)

<div class="topic-metadata">

**Author:** [@milos1](https://discuss.elastic.co/u/milos1)\
**Replies:** 2\
**Last updated:** [November 30, 2022, 10:49am UTC](https://discuss.elastic.co/t/unable-to-see-timeline-section/320070 "2022-11-30T10:49:33Z")

</div>

Trying to visualize the Timeline Section under Security Menu, it automatically redirects me on Get Started page, as you can see from the image in attachment.

---

## [Elasticsearch Kibana API - Case Management filtering via API requests](https://discuss.elastic.co/t/elasticsearch-kibana-api-case-management-filtering-via-api-requests/320136)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 10:30am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-api-case-management-filtering-via-api-requests/320136 "2022-11-30T10:30:12Z")

</div>

Hey all! I'm investigating the REST API of Kibana. I'm interested in the implementation of some automatization processes using our SOAR. I have configured the Webhook for Case Management, and now I get the Cases when s…

---

## [How to create a polar plot with degree (0-360 ° )](https://discuss.elastic.co/t/how-to-create-a-polar-plot-with-degree-0-360/320134)

<div class="topic-metadata">

**Author:** [@Lolo](https://discuss.elastic.co/u/Lolo)\
**Replies:** 0\
**Last updated:** [November 30, 2022, 9:51am UTC](https://discuss.elastic.co/t/how-to-create-a-polar-plot-with-degree-0-360/320134 "2022-11-30T09:51:42Z")

</div>

Hi I want to create a polar chart using data with degree 0-360° and plot some line (aggregated as heatmap line). then, I would like to filter on it (for example in the North, from 330° to 30°). how can I create someth…

---

## [Eliminate Kibana Maps refresh blink](https://discuss.elastic.co/t/eliminate-kibana-maps-refresh-blink/319887)

<div class="topic-metadata">

**Author:** [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Replies:** 4\
**Last updated:** [November 30, 2022, 7:46am UTC](https://discuss.elastic.co/t/eliminate-kibana-maps-refresh-blink/319887 "2022-11-30T07:46:57Z")

</div>

Hi, I know it's probably not possible, but is there a way to disable the 'blink' when Kibana Maps does a refresh? If for not all layers, maybe just for selected layers? It would be awesome!

---

## [Dropdown filter does not apply on chart created using timelion](https://discuss.elastic.co/t/dropdown-filter-does-not-apply-on-chart-created-using-timelion/320109)

<div class="topic-metadata">

**Author:** [@Zaid\_Raza](https://discuss.elastic.co/u/Zaid_Raza)\
**Replies:** 0\
**Last updated:** [November 30, 2022, 6:18am UTC](https://discuss.elastic.co/t/dropdown-filter-does-not-apply-on-chart-created-using-timelion/320109 "2022-11-30T06:18:11Z")

</div>

Hi, I have created a chart using Timelion on canvas. kibana |filters | timelion query=".es(index='traces-apm\*,apm-\*,logs-apm\*,apm-\*,metrics-apm\*,apm-\*',metric=avg:transaction.duration.us, timefield=@timestamp,q=' \_e…

---

## [Need help on creating a Watcher Alert for Packetbeat](https://discuss.elastic.co/t/need-help-on-creating-a-watcher-alert-for-packetbeat/319986)

<div class="topic-metadata">

**Author:** [@AKCG23](https://discuss.elastic.co/u/AKCG23)\
**Replies:** 0\
**Last updated:** [November 29, 2022, 3:27am UTC](https://discuss.elastic.co/t/need-help-on-creating-a-watcher-alert-for-packetbeat/319986 "2022-11-29T03:27:12Z")

</div>

Hi , i have configured Packetbeats in some of my Application servers. I am able to get data in my dashboards. Currently i am looking at creating some Alerts for the network traffic . Is there a template or an example wh…

---

## [Kibana alert](https://discuss.elastic.co/t/kibana-alert/319737)

<div class="topic-metadata">

**Author:** [@niyog](https://discuss.elastic.co/u/niyog)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 10:43am UTC](https://discuss.elastic.co/t/kibana-alert/319737 "2022-11-24T10:43:25Z")

</div>

Hai, i am new to this kibana and i completed the setup and even the logs are coming. I created an alert with the the rule type "Log threshold" and added the rule as below and saved the rule. The alert is working whe…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=165)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=167)
